Thank you for these instructions. The computer is running much better. It is not opening random windows or popup ads. Eazyzoom is no longer in the program list, but there is a folder in C\Users|johnbarbw|AppData\LocalLow. It has 2 folder in it (content and cache) along with a .dat file and several .js files. Is it okay to delete the entire eazyzoom folder ?
I have been using windows defender, but cannot enable it. It says the system has turned it off. The only protection program running at this time is superantispyware. I ended the task and it still would not let me enable it. Please let me know if I should download a regular virus protection program to use instead of using windows defender.
Here are the logs:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.9 (03.31.2015:1)
OS: Windows 8.1 x64
Ran by johnbarbw on Tue 03/31/2015 at 11:32:34.62
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
Successfully stopped: [Service] couponprinterservice
Successfully deleted: [Service] couponprinterservice
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
~~~ Files
Successfully deleted: [File] "C:\Windows\couponprinter.ocx"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\pcdr"
Successfully deleted: [Folder] "C:\Users\johnbarbw\AppData\Roaming\drivercure"
Successfully deleted: [Folder] "C:\Users\johnbarbw\AppData\Roaming\pcdr"
Successfully deleted: [Folder] "C:\Program Files (x86)\amiext"
Successfully deleted: [Folder] "C:\Program Files (x86)\coupons"
Successfully deleted: [Folder] "C:\Program Files (x86)\search extensions"
~~~ FireFox
Successfully deleted the following from C:\Users\johnbarbw\AppData\Roaming\mozilla\firefox\profiles\9kdl8r4j.default\prefs.js
user_pref("extensions.a518dcd9fae80409780aaa9dae0ad4d7b4dd9787b93a445e4b8286df475da9388com50611.50611.cookie.CrossriderNotifier_channels.expiration", "Fri Feb 01 2030 00:00:00
user_pref("extensions.a518dcd9fae80409780aaa9dae0ad4d7b4dd9787b93a445e4b8286df475da9388com50611.50611.cookie.CrossriderNotifier_channels.value", "%7B%22app0%22%3A%22app0%22%2C
user_pref("extensions.a518dcd9fae80409780aaa9dae0ad4d7b4dd9787b93a445e4b8286df475da9388com50611.50611.cookie.CrossriderNotifier_geolocation.expiration", "Tue Mar 31 2015 19:06
user_pref("extensions.a518dcd9fae80409780aaa9dae0ad4d7b4dd9787b93a445e4b8286df475da9388com50611.50611.cookie.CrossriderNotifier_geolocation.value", "%22US%22");
user_pref("extensions.a518dcd9fae80409780aaa9dae0ad4d7b4dd9787b93a445e4b8286df475da9388com50611.50611.cookie.CrossriderNotifier_metadata.expiration", "Sat Mar 28 2015 20:18:13
user_pref("extensions.a518dcd9fae80409780aaa9dae0ad4d7b4dd9787b93a445e4b8286df475da9388com50611.50611.cookie.CrossriderNotifier_metadata.value", "%7B%22appId%22%3A50611%2C%22a
user_pref("extensions.a518dcd9fae80409780aaa9dae0ad4d7b4dd9787b93a445e4b8286df475da9388com50611.50611.internaldb.Resources_meta.value", "%7B%22YT.png%22%3A%7B%22id%22%3A101415
user_pref("extensions.a518dcd9fae80409780aaa9dae0ad4d7b4dd9787b93a445e4b8286df475da9388com50611.50611.internaldb.Resources_resource_1014153.value", "%22data%3Aimage/png%3Bbase
user_pref("extensions.a518dcd9fae80409780aaa9dae0ad4d7b4dd9787b93a445e4b8286df475da9388com50611.50611.internaldb.Resources_resource_1014155.value", "%22%3C%21DOCTYPE%20html%3E
user_pref("extensions.a518dcd9fae80409780aaa9dae0ad4d7b4dd9787b93a445e4b8286df475da9388com50611.50611.internaldb.Resources_resource_1014157.value", "%22//Global%20helpers%5Cnv
user_pref("extensions.a518dcd9fae80409780aaa9dae0ad4d7b4dd9787b93a445e4b8286df475da9388com50611.50611.internaldb.Resources_resource_1014159.value", "%22data%3Aimage/png%3Bbase
user_pref("extensions.a518dcd9fae80409780aaa9dae0ad4d7b4dd9787b93a445e4b8286df475da9388com50611.50611.internaldb.Resources_resource_1014160.value", "%22data%3Aimage/png%3Bbase
user_pref("extensions.a518dcd9fae80409780aaa9dae0ad4d7b4dd9787b93a445e4b8286df475da9388com50611.50611.internaldb.Resources_resource_1014161.value", "%22//%20The%20Impression%2
user_pref("extensions.a518dcd9fae80409780aaa9dae0ad4d7b4dd9787b93a445e4b8286df475da9388com50611.50611.thankyou", "hxxp://crossrider.com/thank_you/50611");
Emptied folder: C:\Users\johnbarbw\AppData\Roaming\mozilla\firefox\profiles\9kdl8r4j.default\minidumps [1 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 03/31/2015 at 11:34:53.18
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
# AdwCleaner v4.200 - Logfile created 31/03/2015 at 11:50:25
# Updated 29/03/2015 by Xplode
# Database : 2015-03-29.1 [Server]
# Operating system : Windows 8.1 (x64)
# Username : johnbarbw - JOHNBARBW-DELL
# Running from : C:\Users\johnbarbw\Desktop\adwcleaner_4.200.exe
# Option : Scan
***** [ Services ] *****
Service Found : tammgF119
Service Found : tammgR119
***** [ Files / Folders ] *****
File Found : C:\Users\johnbarbw\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_moncgiclmgkdhmkagcincfkkikpaggcd_0
File Found : C:\Users\johnbarbw\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\moncgiclmgkdhmkagcincfkkikpaggcd
File Found : C:\Users\johnbarbw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_moncgiclmgkdhmkagcincfkkikpaggcd_0.localstorage
File Found : C:\Users\johnbarbw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_moncgiclmgkdhmkagcincfkkikpaggcd_0.localstorage-journal
File Found : C:\Windows\shost.bin
Folder Found : C:\Program Files (x86)\Lightspark 0.5.3-git
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightspark 0.5.3-git
Folder Found : C:\Users\johnbarbw\AppData\Local\Google\Chrome\User Data\Default\Extensions\moncgiclmgkdhmkagcincfkkikpaggcd
Folder Found : C:\Windows\SysWOW64\SearchProtect
***** [ Scheduled tasks ] *****
Task Found : update-sys
Task Found : update-S-1-5-21-1547884887-3990002442-977762493-1001
Task Found : update-sys
***** [ Shortcuts ] *****
***** [ Registry ] *****
Data Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>
Key Found : HKCU\Software\AppDataLow\Software\AmiExt
Key Found : HKCU\Software\Classes\pokki
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Found : [x64] HKCU\Software\Conduit
Key Found : HKLM\SOFTWARE\AmiExt
Key Found : HKLM\SOFTWARE\Classes\CLSID\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Key Found : HKLM\SOFTWARE\Lightspark Team
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19E8EBBF-55F3-41FB-AC8E-373BA0436939}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8AC6566B-131F-4987-82DF-932CED9FCA23}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Coupon Printer for Windows5.0.1.4
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Lightspark
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{A75BE48D-BF58-4A8B-B96C-F9A09DFB9844}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
***** [ Web browsers ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Mozilla Firefox v36.0.4 (x86 en-US)
-\\ Google Chrome v
[C:\Users\johnbarbw\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\johnbarbw\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\johnbarbw\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Found [Extension] : moncgiclmgkdhmkagcincfkkikpaggcd
-\\ Opera v28.0.1750.48
*************************
AdwCleaner[R0].txt - [3775 bytes] - [31/03/2015 11:50:25]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [3834 bytes] ##########